intermediate~2h

AWS KMS & Encryption

AWS's managed key management service — how encryption keys are created, controlled, and used across AWS services without you handling raw key material yourself.

1
Subtopics

🎓 Learning objectives

  • Explain what a Customer Master Key (KMS key) is and how it differs from a data key
  • Explain envelope encryption and why AWS uses it instead of encrypting large data directly with a KMS key
  • Explain how IAM and KMS key policies work together to control key usage
  • Distinguish AWS-managed, customer-managed, and AWS-owned KMS keys

AWS KMS & Encryption is a Pro topic

Sign in, then upgrade to Pro or Power to unlock this topic and the full AWS curriculum.

📂 Subtopics

Related concepts

iam-fundamentalss3-advanced-featureswaf-shield

Next Step

Continue to Amazon Cognito